mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the toBSON
method. A misuse of the vm
dependency to perform exec
commands in a non-safe environment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mongo-express | Mongo-express_project | * | 0.54.0 (excluding) |